Backup credentials deserve separate protection
If the account that manages backups can be reached from the environment being backed up, the backups can be destroyed by whoever compromises it.
Attackers look for this first, because deleting the copies is what makes payment necessary. Backup systems need their own credentials, not shared with the production environment, and ideally not reachable from it at all. It is the single most consequential piece of backup design and the most frequently skipped.
More on Backups and recovery
- Offline copies break attacker reachabilityReach ends at the last plug
- Immutable backups trade flexibility for protectionSet in concrete
- RPO and RTO answer different questionsTwo different clocks
- Restoring data can restore malware tooThe newest jar is the spoiled one
- Recovery order follows dependenciesBottom crate first
- Backup retention determines how far back you can restore to escape corruption or compromiseAs far back as the rope goes
